CVE-2026-30885

MEDIUM

WWBN AVideo <25.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user without requiring authentication or authorization. An unauthenticated attacker can enumerate user IDs and retrieve playlist information including playlist names, video IDs, and playlist status for any user on the platform. This vulnerability is fixed in 25.0.

Scores

CVSS v3 5.3
EPSS 0.0015
EPSS Percentile 35.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-862 CWE-306 CWE-639
Status published
Products (1)
wwbn/avideo < 25.0
Published Mar 10, 2026
Tracked Since Mar 11, 2026